Back to tools

Local configuration tool

TUIC to sing-box JSON

reduce_rtt is translated to zero_rtt_handshake, the name sing-box actually reads.

Your links stay on this device

Conversion happens entirely in your browser. Links are not uploaded, saved, or placed in the page URL.

This page accepts TUIC links, one per line.
Targets sing-box 1.11 or newer — earlier versions do not accept route rule actions or server_ports.
Routing preset

Conversion result

Why some links are rejected

A parameter that cannot be mapped without changing how the connection behaves is reported rather than dropped. For sing-box that mostly means XHTTP, a transport it does not have at all, plus certificate pinning and TUIC v4 tokens. Renames that sing-box does read — reduce_rtt becoming zero_rtt_handshake — happen here instead of failing quietly on your device.

How to import into sing-box

Save the JSON as your config file, or import it as a local profile in SFI, SFA or SFM. The Proxy selector outbound is already wired up, so switching nodes does not mean editing the file.

How TUIC fields map to sing-box

What this converter actually does, line by line. On the left is how it is written in a TUIC link; on the right is the field it becomes in the sing-box config.

In the linkIn the sing-box configNotes
uuid:password@host:portuuid / password / server / server_portTUIC v5 authenticates with both a UUID and a password; either one missing is an error.
sni / alpntls.server_name / tls.alpnQUIC again, so TLS is implicit and there is no enable flag to set.
congestion_controlcongestion_controlcubic, new_reno or bbr. Note the target names differ by more than punctuation — Mihomo says controller.
udp_relay_modeudp_relay_modenative or quic. udp-relay-mode is accepted as an alias in the link.
reduce_rttzero_rtt_handshakesing-box reads zero_rtt_handshake; a config that says reduce_rtt is silently ignored by it.
disable_snitls.disable_sniIn sing-box this is a shared TLS option, so it lands inside the tls block rather than on the outbound.
tokenRejected with an errorA token means TUIC v4, whose wire format and authentication differ from v5 — there is no safe reinterpretation.

FAQ

Which client do I use after converting TUIC to sing-box?
Use an official sing-box 1.11+ client (SFI, SFA and SFM included). Versions below 1.11 reject the route rule actions this config uses and fail to load.
Is this TUIC converter free, and does it upload my node links?
It is free and needs no account. The conversion is done by JavaScript inside this page, on your own machine: links are never uploaded, never written into the page URL, and never stored. Closing the tab is all the cleanup there is.
Can I convert a subscription link straight to sing-box?
Yes, but paste the body the subscription URL returns — usually one long base64 string — rather than the URL itself, which the browser cannot fetch across origins. Mixed protocols in one subscription are fine. Subscription to sing-box converter
The sing-box config converted fine but will not connect — what now?
This page only translates links into a config: it checks the structure, never whether the server is reachable. Confirm the same link works in the client you copied it from, then check the client version — server_ports and route rule actions need sing-box 1.11 or newer.

Other converters

This creates a one-time local configuration, not an auto-updating subscription. It checks configuration structure, not whether a server is reachable.

© 2026